IP Library › Granted Patent US 12,348,505
Granted Patent B2
US 12,348,505 · App. 17/389,660 · Granted Jul 1, 2025

Byte code monitoring to avoid certificate-based outages

Inventors: Plamen Nedeltchev (San Jose, CA); John Buren Southerland (Sandy, UT)
Assignee: Cisco Technology, Inc.
H04L63/0823H04L63/108H04L63/166H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,348,505
App. No.
17/389,660
Granted
Jul 1, 2025
Kind
B2
Abstract

In one embodiment, a monitoring service deploys a monitoring agent to a client device. The monitoring service receives certificate information for a certificate intercepted by the monitoring agent during an online transaction. The monitoring service determines, based on the certificate information, an expiration time for the certificate intercepted by the monitoring agent. The monitoring service provides an expiration notification for display, in advance of the expiration time for the certificate.

Claims (39)

1. A method comprising:

deploying, by a monitoring service at a controller for an application intelligence platform, a monitoring agent of the application intelligence platform to a client device;

receiving, at the monitoring service, certificate information for a certificate intercepted by the monitoring agent during an online transaction that is distributed over application servers, wherein the monitoring agent uses Java byte code monitoring to intercept the certificate and send the certificate information to the monitoring service;

determining, by the monitoring service and based on the certificate information, an expiration time for the certificate intercepted by the monitoring agent; and

providing, by the monitoring service, an expiration notification for display, in advance of the expiration time for the certificate.

2. The method as in claim 1 , wherein the monitoring agent intercepts the certificate from a handshake response sent to the client device by a primary application server of the application servers.

3. The method as in claim 1 , wherein the monitoring agent intercepts the certificate from a downstream application server during the online transaction of the application servers.

4. The method as in claim 1 , wherein the certificate information indicates a publisher of the certificate and an amount of time until the expiration time for the certificate.

5. The method as in claim 1 , further comprising:

associating the online transaction with the certificate.

6. The method as in claim 5 , further comprising:

determining a degree of criticality for the expiration time, based in part on the online transaction associated with the certificate, wherein the expiration notification indicates the degree of criticality.

7. The method as in claim 1 , further comprising:

re-providing the expiration notification for display, according to a schedule that increases in frequency over time.

8. The method as in claim 1 , wherein the certificate information indicates an owner or user of the certificate, and wherein the expiration notification is provided to that owner or user.

9. The method as in claim 1 , wherein the certificate is a Secure Socket Layer (SSL) or Transport Layer Security (TLS) certificate.

10. An apparatus comprising a controller device for an application intelligence platform, comprising:

one or more network interfaces;

a processor coupled to the one or more network interfaces and configured to execute one or more processes; and

a memory configured to store a process that is executable by the processor, the process when executed configured to:

deploy a monitoring agent to a client device;

receive certificate information for a certificate intercepted by the monitoring agent during an online transaction that is distributed over application servers, wherein the monitoring agent uses Java byte code monitoring to intercept the certificate and send the certificate information to the apparatus;

determine, based on the certificate information, an expiration time for the certificate intercepted by the monitoring agent; and

provide an expiration notification for display, in advance of the expiration time for the certificate.

11. The apparatus as in claim 10 , wherein the monitoring agent intercepts the certificate from a handshake response sent to the client device by a primary application server of the application servers.

12. The apparatus as in claim 10 , wherein the monitoring agent intercepts the certificate from a downstream application server during the online transaction of the application servers.

13. The apparatus as in claim 10 , wherein the certificate information indicates a publisher of the certificate and an amount of time until the expiration time for the certificate.

14. The apparatus as in claim 10 , wherein the process when executed is further configured to:

associate the online transaction with the certificate.

15. The apparatus as in claim 14 , wherein the process when executed is further configured to:

determine a degree of criticality for the expiration time, based in part on the online transaction associated with the certificate, wherein the expiration notification indicates the degree of criticality.

16. The apparatus as in claim 10 , wherein the process when executed is further configured to:

re-provide the expiration notification for display, according to a schedule that increases in frequency over time.

17. The apparatus as in claim 10 , wherein the certificate information indicates an owner or user of the certificate, and wherein the expiration notification is provided to that owner or user.

18. A tangible, non-transitory, computer-readable medium storing program instructions that cause a monitoring service at a controller for an application intelligence platform to execute a process comprising:

deploying, by the monitoring service, a monitoring agent of the application intelligence platform to a client device;

receiving, at the monitoring service, certificate information for a certificate intercepted by the monitoring agent during an online transaction that is distributed over application servers, wherein the monitoring agent uses Java byte code monitoring to intercept the certificate and send the certificate information to the monitoring service;

determining, by the monitoring service and based on the certificate information, an expiration time for the certificate intercepted by the monitoring agent; and

providing, by the monitoring service, an expiration notification alert for display, in advance of the expiration time for the certificate.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 30, 2021
From: NEDELTCHEV, PLAMEN; SOUTHERLAND, JOHN BUREN
To: CISCO TECHNOLOGY, INC.
Reel/Frame 057031/0327 →
Continuity (1)
Related Publication 20230031004A1 · Feb 2, 2023
References Cited (25)
US 7512935B1 · Cobb · 2009 [cited by examiner]
US 8346929B1 · Lai · 2013 [cited by examiner]
US 8935524B1 · Lawrence · 2015 [cited by examiner]
US 9118484B1 · Naik · 2015 [cited by applicant]
US 11593780B1 · Dai Zovi · 2023 [cited by examiner]
US 20050172018A1 · Devine · 2005 [cited by examiner]
US 20060048210A1 · Hildre · 2006 [cited by examiner]
US 20080016337A1 · Morgan · 2008 [cited by examiner]
US 20080232595A1 · Pietrowicz · 2008 [cited by examiner]
US 20090094460A1 · Dedek · 2009 [cited by examiner]
US 20110113239A1 · Fu · 2011 [cited by applicant]
US 20130212663A1 · Edge · 2013 [cited by examiner]
US 20140196108A1 · Barr · 2014 [cited by examiner]
US 20150100786A1 · Xiao · 2015 [cited by applicant]
US 20170171191A1 · Cignetti et al. · 2017 [cited by applicant]
US 20170331854A1 · Reddy · 2017 [cited by examiner]
US 20180097803A1 · Iwanir · 2018 [cited by examiner]
US 20180123802A1 · Graul et al. · 2018 [cited by applicant]
US 20190068580A1 · Amid · 2019 [cited by examiner]
US 20200127854A1 · Mandava · 2020 [cited by examiner]
US 20200236093A1 · Bannister · 2020 [cited by examiner]
US 20210044579A1 · Nelson-Gal · 2021 [cited by examiner]
US 20210126801A1 · Nix · 2021 [cited by examiner]
US 20220217133A1 · Montgomery · 2022 [cited by examiner]
“Proactively Handling Certificate Expiration with ssl-cert-check”; retrieved from <http://prefetch.net/articles/checkcertificate.html> on Mar. 19, 2007; 4 pages. (Year: 2007). [cited by examiner]